Live data from Hacker News

Apple defeats liability for not scanning iCloud for CSAM

blog.ericgoldman.org

211–220 of 597 posts

Re: Apple defeats liability for not scanning iCloud for CSAM

#211

Earlier quoted context omitted.

I think you've imagined this faulty understanding. There are many mechanisms by which Apple could actually decrypt the data despite pinky promises not to. You listed one. There are others.

You're suggesting they purposely put a backdoor into all their custom methods? Why? From a liability standpoint that implies a security breach could result in massive loss of customer data and if it did occur would destroy their privacy image to their customers. I agree with the point that what you actually trust is the company to not insert maliscous code or keys into your protected path but modern systems actually…

> You're suggesting they purposely put a backdoor into all their custom methods? Why?

I'm not sure what you mean by "custom methods", but I'm not saying they have bypassed the e2e encryption - I'm just saying that they technically could.

And as for why they would do that, they might get compelled by a government to do it secretly. As far as I know that hasn't happened yet but I see no reason it couldn't and it would take a whistleblower to find out.

> Security wise it's amazing. If a company's admin cannot take your data it's excedingly hard for a hacker to do so.

I agree, it is the best option available. But Apple/Meta are technically lying when they say it's impossible for them to read your messages.

Re: Apple defeats liability for not scanning iCloud for CSAM

#212

I am not a lawyer. There is something ironic about US laws that attempt to prevent crime A by outlawing action B. For example: * A: physical sexual abuse of children. B: possession or distribution of CSAM * A: drug trafficking or tax evasion. B: structured cash withdrawals The irony is that the more B is prevented, the less A can be detected and the less B can be used as evidence of A. It's my understanding that conv…

It's even worse than that. If you make withdrawals with the intent of evading currency reporting requirements you've committed a crime even if the withdrawals don't constitute structuring.

Also, in regard to the fictional CSAM depictions that stuff is still wending its way through the courts.

Re: Apple defeats liability for not scanning iCloud for CSAM

#213

IMO "end-to-end encryption" simply isn't possible when the application is run by the same company as the servers the data sits on, is closed source, and can at any time, see the decrypted contents of data it downloads from their servers and do whatever they want with it. Same issue with Proton, MEGA, and any other e2ee app... it's only useful when the company decides not to mess with the data it could always decrypt…

Only if the company misleads and adds a backdoor to the front-end app (thus this entire discussion). If the company is misleading, any encryption technology is irrelevant anyway.

The company can provide secure enclave and allow the architecture to be audited by third parties.

Which apple does.

It's largely academic though, as almost nobody opts-in to escalated e2e posture in apple services unless they're a high risk person (journalist, dissident, etc).

The headaches that come from e2e everything are too great for most people.

Re: Apple defeats liability for not scanning iCloud for CSAM

#214
post #189

Earlier quoted context omitted.

Stop making stuff up man, the image was uploaded to Google Photos servers. > The father uploaded photos of his son’s genitals, which were also backed up on his Google cloud, to the health care provider’s messaging system as requested.

Did he set up his device to upload his private data to Google, or did Google create an OS that automatically sent everyone's private data to their AI server for scanning without explicit consent?

Google Photos does ask you for consent when you run it.

(It is, granted, a bit pushy about it and will ask multiple times when you run it with an intrusive dialog.)

Re: Apple defeats liability for not scanning iCloud for CSAM

#215

It is crazy people think apple isnt on the side of privacy. Are they perfect? Not even close, but compared to the rest of big tech theyre simply on another level. Apple could easily not do this stuff and it may even be easier to not.

> It is crazy people think apple isnt on the side of privacy.

Look up the "iCloud Keychain" API:

For years Apple has let and helped Facebook, TikTok, Tinder etc. track users even after you delete an app, even ACROSS DEVICES and DEVICE RESETS.

There's no way to even SEE what data the apps have stored on your device & iCloud account on iOS, only through the macOS Keychain Access app. Even then you can't be sure that that's all that being stored.

They temporarily changed course and wiped iCloud Keychain data when deleting apps, but only during a single beta of iOS some years ago, and then reverted to the way it is now.

This scores so many points in favor of privacy intruding corporations that it puts Apple far from being the paragon of privacy they pretend to parade as.

Re: Apple defeats liability for not scanning iCloud for CSAM

#216

Earlier quoted context omitted.

Yes, this is an argument that exists. But it's not supported by evidence. It's the same as the old "video game violence should be outlawed because it might cause real violence", which is just as unsubstantiated.

Yeah, that old canard is ridiculous! I mean, if there were any truth to it, surely our nation would have seen an uptick, in the past 30–40 years, of new generations picking up guns and just mercilessly mowing down soft targets as if playing GTA. Thankfully, that is all confined to fantasy in cyberspace!

gta is played all around the world yet only one country is an outlier in mass shootings.

perhaps there is more to it?

Re: Apple defeats liability for not scanning iCloud for CSAM

#217

Maybe my perception is off, but it seems like there's a huge push by the legislature and some people to do anything and everything to prevent CSAM, yet almost nothing seems to be done to prevent CSA. For CSAM, there's all sorts of monitoring, scanning, identify capturing, etc. But it's all after abuse has taken place, and it seems that many of the people actually arrested are arrested for CSAM and not CSA. This has e…

>if that gets extended to

If you provide the government a platform to do So, they'll do Y if you wait long enough

Re: Apple defeats liability for not scanning iCloud for CSAM

#218
post #191

Earlier quoted context omitted.

Police can absolutely open snail mail with an appropriate warrant when investigating traffickers.

With a signed warrant being the key differentiator vs invading privacy by default.

I agree, so let's make sure that signed warrant is always required for any kind of access to communications, even _if unencrypted_ like snail mail, SMS or plain text chat client. As well as encrypted.

So - political solution, not a tech solution.

Re: Apple defeats liability for not scanning iCloud for CSAM

#219
post #7

The judge called the outcome disturbing, as it leaves victimized children as "collateral damage" of privacy protections. As sad as this is, end to end encryption means no CSAM scanning. As an alternative Apple previously tried to do scanning on the phones locally but caught hell for that too. This is one of those unfortunate tradeoffs but I see no alternative to privacy taking priority.

Truly being honest, I think CSAM scanning of private comms is ineffective in the long term anyways. Pedophiles aren't stupid, you'll drag a bunch at first but the networks will be reestablished and sharing will be done via sneakernet. The primary focus should always in preventing the creation of CSAM. - Comprehensive Sex Ed starting young so kids can identify grooming and seek help from a trusted adult, even if abuse…

> Pedophiles aren't stupid

I'm not entirely convinced that's true. Facebook is a leading reporter of CSAM, much of it sent through Messenger, which only recently got E2EE, and Instagram DM, which briefly had E2EE but no longer does. If I was going to transmit something that could get me in trouble, it certainly wouldn't be via Instagram DM.

Facebook's EU CSAM report is here: https://transparency.meta.com/reports/regulatory-transparenc...

Re: Apple defeats liability for not scanning iCloud for CSAM

#220

I am not a lawyer. There is something ironic about US laws that attempt to prevent crime A by outlawing action B. For example: * A: physical sexual abuse of children. B: possession or distribution of CSAM * A: drug trafficking or tax evasion. B: structured cash withdrawals The irony is that the more B is prevented, the less A can be detected and the less B can be used as evidence of A. It's my understanding that conv…

I don't think there's a particular connection between indirect enforcement mechanisms and inability to detect the crime, though: - Structured transactions are illegal because we put a minimum on the amount of cash that has to move before government financial surveillance applies. The alternative (at least, one acceptable to the state) would be that the government knows every transaction you make[0] no matter the size…

> As for drawn child porn, involving fictional characters (i.e. not CSAM), it is legal in certain jurisdictions. Notably, America, where the 1st Amendment errs on the side of creative expression

As I noted in another comment:

Currently this is explicitly against the law[0]:

  (a)In General.—Any person who, in a circumstance described in subsection (d), knowingly produces, distributes, receives, or possesses with intent to distribute, a visual depiction of any kind, including a drawing, cartoon, sculpture, or painting, that—
    (1)
      (A)depicts a minor engaging in sexually explicit conduct; and
      (B)is obscene; or ...
  (b)...
  (c)Nonrequired Element of Offense.—
  It is not a required element of any offense under this section that the minor depicted actually exist.
It is not a required element of any offense under this section that the minor depicted actually exist.

[0]https://www.law.cornell.edu/uscode/text/18/1466A

Post reply on HN